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Art Unit: 2137 

DETAILED ACTION 

1 . In view of the Appeal Brief filed on 6-28-2005 PROSECUTION IS 
HEREBY REOPENED. New Rejections set forth below. 

To avoid abandonment of the application, appellant must exercise one of 
the following two options: 

(1 ) file a reply under 37 CFR 1.111 (if this Office action is non-final) or a 
reply under 37 CFR 1.113 (if this Office action is final); or, 

(2) initiate a new appeal by filing a notice of appeal under 37 CFR 41 .31 
followed by an appeal brief under 37 CFR 41 .37. The previously paid notice of 
appeal fee and appeal brief fee can be applied to the new appeal. If, however, 
the appeal fees set forth in 37 CFR 41 .20 have been increased since they were 
previously paid, then appellant must pay the difference between the increased 
fees and the amount previously paid. 

A Supervisory Patent Examiner (SPE) has approved of reopening 
prosecution by signing below: 



2. Claims 1-12, 19-21 and 24 are pending in this application and have been 
examined. 
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Claim Rejections - 35 USC § 103 

3. The following is a quotation of 35 U.S.C. 103(a) which forms the basis for 
all obviousness rejections set forth in this Office action: 

(a) A patent may not be obtained though the invention is not identically disclosed or described 
as set forth in section 102 of this title, if the differences between the subject matter sought to 
be patented and the prior art are such that the subject matter as a whole would have been 
obvious at the time the invention was made to a person having ordinary skill in the art to which 
said subject matter pertains. Patentability shall not be negatived by the manner in which the 
invention was made. 

4. Claims 1-12 and 19-21 are rejected under 35 U.S.C. 103(a) as being 
unpatentable over; Zone Labs: "Zone Alarm Help", 6/2001 ; S. Boran: "Personal 
Firewalls / Intrusion Detection Systems, An Analysis of Mini-Firewalls for 
Windows Users", 11/1999-12/2000; Smart Computing, "Reviews: Hack Tracer 
1.2", Smart Computing, January 2001, Vol. 12 Issue 1. 

As for claim 1 , Zone Labs teaches a method for summarizing firewall 
activity, comprising: 

(a) organizing a plurality of types of events associated with a firewall of a 
local computer into a plurality of categories (Getting Started, Tutorial, Quick Tour, 
page 5: "Alert Setting: Log Alerts to a text file", page 6: "Current Alerts") 

(b) tracking a number of occurrences of each type of event utilizing the 
firewall (Getting Started: "The Alerts Panel", page 2: "Internet Alerts 3 rd of 3 
alerts"); and 

(c) displaying a graphical representation indicating a severity of the 
number of the events utilizing the firewall (Use The Internet: "Firewall Alerts" 
page 1 ), wherein a selector is displayed for setting a blocking level of the firewall 
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to a desired blocking level (Getting Started, Tutorial, Quick Tour: "Alert Setting", 
page 8); wherein a plurality of interface features are displayed including a 
summary interface (Getting Started, Tutorial, Quick Tour: "Alert Setting", page 5), 
an Internet protocol (1P) address interface (Getting Started, Tutorial, Quick Tour: 
"Local Zone Settings", page 9) , an event log (Getting Started, Tutorial, Quick 
Tour, page 5: "Alert Setting: Log Alerts to a text file", page 6: "Current Alerts"), 
and a notification option interface (Getting Started, Tutorial, Quick Tour, page 5: 
"Alert Setting: Log Alerts to a text file", page 6: "Alert Settings"), wherein: upon 
the selection of the summary interface, displaying a recent activity list including 
total blocked access attempts by remote computers (Getting Started, Tutorial, 
Quick Tour, page 5: "Alert Setting: Log Alerts to a text file", page 6: "Current 
Alerts"), upon the selection of the event log, displaying a log of the blocked 
access attempts by the remote computers (Getting Started, Tutorial, Quick Tour, 
page 5: "Alert Setting: Log Alerts to a text file", page 6: "Alert Settings"), and 
upon the selection of the notification option interface, displaying a plurality of 
notification options for selection (Getting Started, Tutorial, Quick Tour, page 5: 
"Alert Setting: Log Alerts to a text file", page 6: "Current Alerts"); wherein a 
lock-down option is provided for selectively blocking all access attempts via an 
interface (Getting Started, Tutorial, Quick Tour, "Internet Lock," page 10); 
wherein the user is capable of selecting the IP addresses associated with the 
remote computers to be allowed access (Getting Started, Tutorial, Quick Tour, 
"Local Zone Properties", page 9); wherein the user is capable of selecting a list of 
application programs to be allowed to communicate over a network (Getting 
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Started, Tutorial, Quick Tour, "Program Control", page 10). Zone Labs does not 
explicitly teach a graphical representation that includes a graph of the number of 
alerts. However Eschelbeck et ah, US 6,567,808, does teach this feature (fig. 6, 
"Cyber Cop Monitor Results, Graphical Representation"). Zone Labs does not 
explicitly teach that, upon the selection of the IP address interface, displaying the 
IP address interface for selecting the IP addresses associated with the remote 
computers to be blocked or wherein the user is capable of selectively blocking 
Internet control message protocol (ICMP) traffic However Boran teaches such as 
features of the PGP7 firewall ("Personal Firewall Test: PGP7, features"). Zone 
Labs does not explicitly teach a firewall wherein a user is capable of performing a 
visual trace. However Smart Computing does teach such as a feature of the 
Hack Tracer 1 .2 firewall (reviews, January 2001 , Vol. 12 Issue 1 ). Therefore it 
would have been obvious to one of ordinary skill in the art at the time of the 
invention to have incorporated these features into the firewall of Zone labs. It 
would have been desirable to do so as blocking ICMP traffic, blocking specific IP 
addresses, and performing a trace on such an address would allow for greater 
flexibility in configuring firewall security 

As for claim 2, Zone Labs teaches the method as recited in claim 1 , 
wherein the events include blocked attempts of various types (Getting Started, 
Tutorial, Quick Tour, "Alert Setting: Log Alerts to a text file", page 6: "Current 
Alerts"). 
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As for claim 3, Zone Labs teaches the method as recited in claim 2, 
wherein at least one of the types of the blocked attempts includes blocked 
attempts of the remote -computers to access predetermined banned ports 
associated with the local computer selection (Getting Started, Tutorial, Quick 
Tour, "Alert Setting: Log Alerts to a text file", page 6: "Current Alerts"). 

As for claim 4, Zone Labs teaches the method as recited in claim 2, 
wherein at least one of the types of the blocked attempts includes blocked 
attempts of the remote computers with a predetermined set of IP addresses to 
access the local computer selection (Getting Started, Tutorial, Quick Tour, "Alert 
Setting: Log Alerts to a text file", page 6: "Current Alerts", and "Local Zone 
Properties", page 9). 

As for claim 5, Zone Labs teaches the method as recited in claim 2, 
wherein at least one of the types of the blocked attempts includes blocked 
attempts to access the network made by predetermined applications (Getting 
Started, Tutorial, Quick Tour, Alerts, "More Info Button" page 2). 

As for claim 6, Zone Labs teaches the method as recited in claim 1 , 
wherein the displayed number of occurrences of each type of event occurred 
within a predetermined time period (Getting Started, Tutorial, Quick Tour, "Alert 
Setting: Log Alerts to a text file", page 6: "Current Alerts", where there is kept a 
log file for each predetermined 24 hour period). 
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As for claim 7, Zone Labs teaches the method as recited in claim 1 , and 
further comprising displaying additional information relating to the events upon as 
selection thereof (Getting Started, Tutorial, Quick Tour, "Alert Setting: Log Alerts 
to a text file", page 6: "Current Alerts", and Getting Started, Tutorial, Quick Tour, 
Alerts, "More Info Button" page 2). 

As for claim 8, Zone Labs teaches the method as recited in claim 2, 
wherein a first type of the blocked attempts includes blocked attempts of the 
remote computers to access predetermined banned ports associated with the 
local computer, a second type of the blocked attempts includes blocked attempts 
of the remote computers with a predetermined set of IP addresses to access the 
local computer, and a third type of the blocked attempts includes blocked 
attempts to access the network made by predetermined applications (Getting 
Started, Tutorial, Quick Tour, Alerts, "More Info Button" page 2). 

As for claim 9, Zone Labs teaches the method as recited in claim 8, 
wherein the first type of the blocked attempts, the second type of the blocked 
attempts, and the third type of the blocked attempts are organized into the 
categories (Getting Started, Tutorial, Quick Tour, Alerts, "More Info Button" page 
2). 

As for claim 10, Zone Labs teaches the method as recited in claim 8, 
wherein a plurality of banned ports associated with the first type of the blocked 
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attempts are displayed with the number of the occurrences associated therewith 
(Getting Started, Tutorial, Quick Tour, Alerts, "More Info Button" page 2). 

As for claim 1 1 , Zone Labs teaches the method as recited in claim 8, 
wherein a plurality of banned IP addresses associated with the second type of 
the blocked attempts are displayed with the number of the occurrences 
associated therewith (Getting Started, Tutorial, Quick Tour, "Alert Setting: Log 
Alerts to a text file", page 6: "Current Alerts", and Getting Started, Tutorial, Quick 
Tour, Alerts, "More Info Button" page 2). 

As for claim 12, Zone Labs teaches the method as recited in claim 8, 
wherein a plurality of banned applications associated with the third type of the 
blocked attempts are displayed with the number of the occurrences associated 
therewith (Getting Started, Tutorial, Quick Tour, "Alert Setting: Log Alerts to a text 
file", page 6: "Current Alerts", and Getting Started, Tutorial, Quick Tour, Alerts, 
"More Info Button" page 2). • 

As for claims 19, 20, and 21 , the claims are directed towards the computer 
program product embodied on a computer readable memory medium that when 
read out cause the means, and the logic enumerated to carry out the method of 
claim 1 . Therefore these claims are rejected on the same basis as is claim 1 . 
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Allowable Subject Matter 



5. 



Claim 24 is allowed. 



Conclusion 



6. Any inquiry concerning this communication or earlier communications from 
the examiner should be directed to Paul E. Callahan whose telephone number is 
(571) 272-3869. The examiner can normally be reached on M-F from 9 to 5. 

If attempts to reach the examiner by telephone are unsuccessful, the 
Examiner's supervisor, Emmanuel Moise, can be reached on (571 ) 272-3865. 
The fax phone number for the organization where this application or proceeding 
is assigned is: (571 ) 273-8300. 
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